[#106355] [Ruby master Bug#18373] RBS build failure: '/include/x86_64-linux/ruby/config.h', needed by 'constants.o'. — "vo.x (Vit Ondruch)" <noreply@...>
Issue #18373 has been reported by vo.x (Vit Ondruch).
28 messages
2021/12/01
[ruby-core:106791] [Ruby master Bug#18424] Is Ruby is vulnerable to log4j?
From:
deivid <noreply@...>
Date:
2021-12-23 17:36:55 UTC
List:
ruby-core #106791
Issue #18424 has been updated by deivid (David Rodr鱈guez). Yes, that's correct. The naming in these test cases is inspired by rearward packages, but these are just dummy packages just for the sake of testing, not the real library code. You can replace `log4j` with `very-secure-library` in those tests and they should still pass. ---------------------------------------- Bug #18424: Is Ruby is vulnerable to log4j? https://bugs.ruby-lang.org/issues/18424#change-95495 * Author: salamani (Ravi Salamani) * Status: Rejected * Priority: Normal * ruby -v: master * Backport: 2.6: UNKNOWN, 2.7: UNKNOWN, 3.0: UNKNOWN ---------------------------------------- I observed that the ruby uses zookeeper, dep "slyphon-log4j", "= 1.2.15". Is Ruby is vulnerable to log4j? -- https://bugs.ruby-lang.org/ Unsubscribe: <mailto:ruby-core-request@ruby-lang.org?subject=unsubscribe> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-core>